|
213671
|
7.5 |
HIGH
Network
|
online_store_system_project
|
online_store_system
|
Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.
|
CWE-22
Path Traversal
|
CVE-2019-8291
|
2024-11-21 13:49 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213672
|
6.1 |
MEDIUM
Network
|
online_store_system_project
|
online_store_system
|
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included …
|
CWE-79
Cross-site Scripting
|
CVE-2019-8290
|
2024-11-21 13:49 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213673
|
5.4 |
MEDIUM
Network
|
online_store_system_project
|
online_store_system
|
Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
|
CWE-79
Cross-site Scripting
|
CVE-2019-8289
|
2024-11-21 13:49 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213674
|
5.4 |
MEDIUM
Network
|
online_store_system_project
|
online_store_system
|
Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8288
|
2024-11-21 13:49 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213675
|
7.5 |
HIGH
Network
|
adobe google debian fedoraproject
|
flash_player_desktop_runtime flash_player chrome debian_linux fedora
|
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current u…
|
NVD-CWE-noinfo
|
CVE-2019-8075
|
2024-11-21 13:49 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213676
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the…
|
CWE-22
Path Traversal
|
CVE-2019-8074
|
2024-11-21 13:49 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213677
|
9.8 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code …
|
CWE-77
Command Injection
|
CVE-2019-8073
|
2024-11-21 13:49 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213678
|
7.5 |
HIGH
Network
|
adobe
|
coldfusion
|
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of t…
|
NVD-CWE-noinfo
|
CVE-2019-8072
|
2024-11-21 13:49 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213679
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
OpenEMR v5.0.1-6 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8368
|
2024-11-21 13:49 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213680
|
7.2 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR v5.0.1-6 allows code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-8371
|
2024-11-21 13:49 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|